Compliance
CDD (Customer Due Diligence)
Customer Due Diligence
Definition
The baseline KYC and risk assessment performed on every customer at onboarding. Distinct from Enhanced Due Diligence applied to higher-risk profiles.
Why it matters
CDD is the foundation layer of AML compliance. Every player goes through CDD at registration: identity verification, basic background risk assessment, sanctions and PEP screening, and assignment of an initial risk rating that determines subsequent monitoring intensity. The scope and depth of CDD is set by the operator's risk-based approach and the jurisdiction's specific requirements.
Modern CDD has become heavily automated. eKYC tools verify identity from documents and biometrics in seconds; sanctions and PEP lists are checked via API; risk scoring runs in the background. The customer-facing experience can be near-instant for clean low-risk players, while higher-risk profiles are routed to manual review. The trade-off is calibration: lighter-touch CDD reduces friction and improves conversion but raises compliance risk; heavier CDD does the opposite. Risk-based approach is the regulator-accepted way to balance these, and audited evidence of how the operator calibrated the approach is what gets scrutinized in regulatory inspections.
Frequently asked questions
When does CDD escalate to EDD?
When the customer's risk profile triggers thresholds defined in the operator's AML policy. Common triggers include high deposit volume, complex source of funds patterns, PEP status, residence in higher-risk jurisdictions, or behavioral red flags from transaction monitoring.
Is CDD a one-time check or ongoing?
One-time at onboarding for the formal CDD step, but ongoing monitoring of the same data points is required. CDD is refreshed when material changes occur (address, payment method, behavior) or on periodic schedules for higher-risk profiles.